Phishing Hack
What happened
On October 10, 2024, a phishing attack led to the loss of $2.47 million in Aave Ethereum sDAI after a user unknowingly signed a malicious "permit" signature.
The victim signed a fraudulent "permit" transaction that allowed the scammer to gain control of the sDAI tokens. The scam involved temporary addresses pre-computed using the CREATE2 function, commonly used in phishing schemes to deceive victims into granting access to their assets.
Victim Address: 0xfcc5acd5…d403c2
Scammer Address: 0xAc68803B…67E7f2
Transaction Hash: https://etherscan.io/tx/0x64a00980…86454f
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.